Logs, Endpoint, Network and Cloud Investigation
This area tests log source selection, endpoint telemetry, packet and flow analysis, cloud audit trails, evidence handling, and investigation conclusions.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Investigations depend on collecting relevant evidence from endpoints, networks, identity providers, applications, and cloud control planes.
Exam cue: Pick the log source that can observe the event.
Concept 2
Different logs answer different questions: who, what, where, when, how, and whether the action succeeded.
Exam cue: Use timestamps, identity, source, destination, and action fields together.
Concept 3
Evidence handling requires integrity, chain of custody, scope control, and careful documentation.
Exam cue: Preserve evidence before making broad changes.
Risk pitfalls and guardrails
Using firewall logs to answer host process questions.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Changing evidence before acquisition or documentation.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring cloud audit logs for control-plane activity.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Endpoint Log
Endpoint logs show host activity such as processes, files, users, services, and detections.
Network Flow
Network flow records summarize communication metadata such as source, destination, port, protocol, and volume.
Packet Capture
Packet capture records packet-level details for deeper network analysis.
DNS Log
DNS logs show name lookups that may reveal command-and-control or phishing activity.
Authentication Log
Authentication logs show sign-in attempts, success, failure, source, and identity context.
Cloud Audit Log
Cloud audit logs record control-plane actions such as API calls, identity changes, and resource updates.
Time Synchronization
Time synchronization keeps event timestamps comparable across systems.
Chain of Custody
Chain of custody documents who handled evidence, when, how, and why.
Forensic Image
A forensic image is a preserved copy used for investigation without altering the original.
Evidence Integrity
Evidence integrity is protected through hashing, documentation, and controlled handling.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
An analyst needs to see which processes started, which files changed, and which user was active on a compromised laptop. Which source is most useful?
A company retains source IP, destination IP, ports, protocol, byte count, and session time but not payloads. What data is this?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
